Legal
Data Processing Agreement
Last updated: September 2026
Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between RealTime.Photos (operated by Nanjing Zhiyin Trading Co., Ltd.) and the photographer or organisation using the platform ("Controller"). It governs the processing of personal data that the Controller uploads to the platform in the course of using the service.
By accepting the Terms of Service, the Controller enters into this DPA. Where applicable law requires a separately signed agreement, the Controller may request a countersigned copy by emailing hello@realtime.photos with the subject line "DPA Request".
Definitions
Applicable Data Protection Law means the EU General Data Protection Regulation (GDPR 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and any other applicable national or state-level data protection or privacy legislation.
Controller means the photographer or organisation that determines the purposes and means of processing personal data uploaded to RealTime.Photos.
Processor means RealTime.Photos (Nanjing Zhiyin Trading Co., Ltd.), which processes personal data on behalf of the Controller.
Sub-Processor means any third-party processor engaged by RealTime.Photos to process personal data in the course of providing the service.
Data Subjects means the individuals whose personal data is contained in content uploaded by the Controller.
The terms Personal Data, Processing, Data Breach, and other capitalised data protection terms have the meanings given to them in the GDPR.
Roles & responsibilities
The Controller is the data controller for the personal data of event guests and other individuals whose images are uploaded to the platform. RealTime.Photos is the data processor, processing that data solely on the Controller's behalf and in accordance with this DPA and the Controller's documented instructions (as set out in the Terms of Service).
The Controller is responsible for:
- Ensuring it has complied with its transparency obligations to data subjects under GDPR Articles 13–14 (or equivalent under applicable law), including disclosing that face recognition is in use at the event. The platform's Print-ready QR card (Share tab) is designed for this.
- Ensuring that the chosen consent configuration satisfies its obligations under GDPR Article 9(2). Two configurations are available: (i) pre-event consent, in which the Controller collects consent from attendees before the event through a registration form or privacy notice, so that consent is already in place when photos are uploaded; and (ii) in-app consent, in which guests who choose to use face search are shown a consent screen by RealTime.Photos before any photos of them are surfaced. In-app consent is the default for new events. For events created under an Agency Plan, pre-event consent is pre-selected at creation. Either configuration can be chosen on any plan, at creation or at any time afterwards from the event's settings. Where it is used, the in-app wizard is suppressed and the Controller is responsible for ensuring that attendees have given consent before the event. RealTime.Photos provides ready-to-use consent language from the dashboard to assist with this. The Controller, as data controller, is responsible for ensuring the chosen configuration satisfies Article 9(2)(a) or equivalent applicable law.
- Ensuring that any transfer of personal data to RealTime.Photos complies with applicable cross-border transfer rules.
- Obtaining consent from a parent or guardian for attendees below the age of consent under applicable law (14 in Spain), whichever consent configuration is used. RealTime.Photos cannot determine a person's age before face recognition runs.
Details of processing
The subject matter, duration, nature, and purpose of processing carried out by RealTime.Photos as Processor are as follows:
| Subject matter | Operation of the RealTime.Photos event gallery platform on behalf of the Controller |
| Duration | Raw per-face biometric attributes (age range, gender, emotion signals) are deleted within 48 hours of the last photo upload, and in practice within minutes of face recognition completing for that upload; the 48-hour figure is an outer limit enforced by a scheduled job. Face embeddings stored in AWS Rekognition are purged 12 months after the first photo upload. All remaining event data is deleted according to the Controller's plan schedule (7–90 days after the event's first photo upload, or sooner on account deletion). For Custom-plan events, the retention period is agreed per contract. For Agency Plan events, data is retained for the contract duration plus a 30-day wind-down after expiry. |
| Nature | Storage, retrieval, display, format conversion, compression, and metadata (EXIF/GPS) removal of photographic content; face indexing when a photo is uploaded, for events with face recognition enabled; grouping of detected faces into clusters and generation of face thumbnails; estimation of face attributes (age range, gender, smile, emotion) and their aggregation; co-appearance analysis between clusters; text recognition in photos where enabled; selfie-based matching; consent recording; email delivery of reports requested by the Controller; and, when a data subject uses the removal tool, searching events for that person's face to delete matching data |
| Purpose | Enabling event guests to view and filter photos via the guest gallery; selfie-based photo search; aggregate audience statistics and, for guests who opt in, personal event recaps with sentiment and networking connection counts; text search and brand exposure reports where enabled; like and analytics features; handling data subject removal requests |
| Personal data types | Photographic images (which may depict identifiable individuals); biometric identifiers derived from face recognition (face vectors/embeddings); face thumbnails; per-face quality signals (sharpness, head angle); transient per-face attribute estimates (age range, gender, smile, emotion; retained up to 48 hours, typically minutes); per-cluster attribute summaries (kept until the event is deleted); co-appearance counts between clusters; text detected in photos (where enabled); guest consent timestamps |
| Data subject categories | Any individual whose image appears in photos uploaded by the Controller, including event attendees and guests, staff, suppliers, bystanders and, where present, minors |
| Special categories | Biometric data (facial images and derived biometric identifiers), processed under GDPR Article 9. Face attribute estimates (age range, gender, smile, emotion) are derived from these images: raw per-face estimates are kept only transiently (up to 48 hours, typically minutes), and a per-cluster summary is kept until the event is deleted. These estimates describe how a face appears in a photo and are not a determination of a data subject's internal emotional state. Two consent configurations are available: (i) pre-event consent, in which the Controller collects consent from attendees through a registration form or privacy notice before photos are uploaded; or (ii) in-app consent, in which guests who choose to use face search are shown a consent screen before any photos of them are surfaced. Under in-app consent, a guest who has not consented is not shown to other guests at all: they do not appear in the gallery's face row, and no image of their face is served to other attendees. In-app consent is the default for new events; for events created under an Agency Plan, pre-event consent is pre-selected, and either configuration can be chosen on any plan. Under both configurations, guests who do not consent or who never interact with face search are never shown face-matched results. The Controller is responsible for ensuring its chosen configuration satisfies GDPR Article 9(2)(a) or equivalent applicable law, and for fulfilling its Articles 13–14 transparency obligations to attendees. The platform's Print-ready QR card (Share tab) is designed to support this. |
Processor obligations
(a) Instructions. RealTime.Photos processes personal data only on documented instructions from the Controller, as set out in the Terms of Service and this DPA. If RealTime.Photos is required by applicable law to process data for another purpose, it will inform the Controller before doing so, unless prohibited by law. RealTime.Photos will also promptly inform the Controller if, in its reasonable opinion, any instruction from the Controller would cause it to infringe Applicable Data Protection Law, and may suspend the affected processing until the Controller confirms or changes that instruction.
(b) Confidentiality. RealTime.Photos ensures that all personnel authorised to process the Controller's personal data are subject to appropriate confidentiality obligations.
(c) Security. RealTime.Photos implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. Current measures include:
- Encryption in transit: all data transmitted between clients, the application, and sub-processors is encrypted using TLS 1.2 or higher.
- Encryption at rest: photos in AWS S3 are encrypted with server-side encryption (SSE-S3, AES-256), and our database provider encrypts stored data at rest.
- Access controls: access to production systems is restricted to a minimum number of named, authorised personnel, and photographer accounts are protected by a password plus an emailed verification code, or by Google sign-in.
- Pseudonymisation: face recognition embeddings are stored separately from photo metadata, reducing the risk of re-identification in the event of a partial breach.
- Incident response: RealTime.Photos maintains documented incident detection and response procedures.
More detailed information about technical and organisational security measures is available on written request.
(d) Sub-processors. RealTime.Photos engages sub-processors as listed in the Sub-processors section below. By entering into this DPA, the Controller grants general written authorisation for the engagement of those sub-processors. RealTime.Photos will notify the Controller of any intended addition or replacement of a sub-processor by updating this DPA and notifying registered account holders by email or in-app notice at least 14 days in advance. The Controller may object in writing within 14 days of such notice. If the Controller objects and RealTime.Photos cannot reasonably accommodate the objection without engaging the new sub-processor, the Controller may terminate the affected service without penalty, effective 30 days after written notice of termination.
(e) Data subject rights. RealTime.Photos will assist the Controller in fulfilling its obligations to respond to data subject rights requests — including access, rectification, erasure, restriction, portability, and objection — by providing available data, deletion tools, and export functionality via the dashboard or, where not available via the dashboard, upon written request to hello@realtime.photos.
(f) Data breach notification. RealTime.Photos will notify the Controller without undue delay — and in any event within 48 hours of becoming aware — of any confirmed personal data breach affecting the Controller's data. The notification will include: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and measures taken or proposed.
(g) Return and deletion. Upon termination of the service or upon request, RealTime.Photos will delete or return all personal data in accordance with the data retention schedule in the Terms of Service. Upon request, RealTime.Photos will provide written certification of deletion within 30 days of the request.
(h) Audit. RealTime.Photos will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits or inspections conducted by the Controller or a mandated auditor, subject to: reasonable written notice of at least 30 days; a frequency of no more than once per calendar year; and the auditor being bound by appropriate confidentiality obligations.
(i) DPIA and prior consultation support. Where the Controller is required to conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35 in relation to processing carried out by RealTime.Photos, we will provide reasonable assistance — including making available relevant information about our processing activities, security measures, and sub-processors. Where required, we will also assist with any prior consultation with the relevant supervisory authority under GDPR Article 36.
(j) Records of processing. RealTime.Photos maintains records of processing activities carried out on behalf of Controllers, as required by GDPR Article 30(2). These records include the categories of processing performed, the sub-processors engaged, and information about international data transfers. Records are maintained in written form and made available to supervisory authorities upon request.
Sub-processors
The following sub-processors are currently engaged by RealTime.Photos to process personal data of the Controller's event guests:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Photo storage (S3) and face and text recognition (Rekognition) | European Union (Spain) | Stored in the EU; SCCs (EU Decision 2021/914) + EU-US DPF for any transfer to the US |
| Convex, Inc. | Database storage — event metadata, face cluster data, analytics counters | European Union (Ireland) | Stored in the EU; SCCs (EU Decision 2021/914) for any transfer to the US |
| Vercel, Inc. | Application hosting and content delivery | United States | SCCs (EU Decision 2021/914) + EU-US DPF |
| Resend | Email delivery of reports requested by the Controller, which may include event photos and face thumbnails | United States | SCCs (EU Decision 2021/914) |
Dodo Payments (payment processing) and Clerk (photographer account authentication) process data of the Controller as an account holder, not data of the Controller's event guests, and are not sub-processors under this DPA.
International transfers
AWS and Convex store and process the Controller's data in the European Union (Spain and Ireland). Vercel and Resend process data in the United States, and AWS and Convex are US-headquartered companies. Personal data transferred from the European Economic Area (EEA) or the United Kingdom to the United States is protected by one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs): EU Commission Decision 2021/914 (for EEA-origin transfers) and the UK ICO's International Data Transfer Addendum (for UK-origin transfers), incorporated into our agreements with each sub-processor.
- EU-US Data Privacy Framework or UK Extension: where a sub-processor holds a current certification under these frameworks, transfers to that entity may additionally rely on the applicable adequacy decision.
The Controller may request a summary of the transfer mechanisms in place for each sub-processor by contacting hello@realtime.photos.
US privacy law
Where the Controller or their data subjects are subject to the CCPA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), or any other applicable US state privacy law, RealTime.Photos agrees to act as a "service provider" or "processor" as defined under the applicable law, and will:
- Process personal data only for the business purposes specified in this DPA and the Terms of Service, and not sell or share it for cross-context behavioural advertising.
- Not retain, use, or disclose personal data for any purpose other than providing the service, except as permitted by applicable law.
- Assist the Controller in meeting its obligations to respond to consumer rights requests — including access, deletion, correction, and opt-out — in relation to personal data processed on the Controller's behalf.
- Notify the Controller promptly if RealTime.Photos determines it can no longer meet its obligations under applicable US privacy law.
Changes to this DPA
We may update this DPA from time to time to reflect changes in Applicable Data Protection Law, platform features, or sub-processor arrangements. We will provide at least 14 days' advance notice of material changes by email or in-app notice to registered account holders. Continued use of the platform after the effective date constitutes acceptance of the revised DPA.
Where applicable law requires a separately executed DPA, the Controller may request a countersigned copy of the current version at any time by contacting hello@realtime.photos with the subject line "DPA Request".
Governing law
This DPA is governed by the laws of Spain and the European Union. Where the Controller is established in the United Kingdom, this DPA shall be interpreted consistently with UK data protection law (UK GDPR and the Data Protection Act 2018). Where the Controller is subject to US state privacy law, the provisions of the US Privacy Law section above apply concurrently and are not limited by this governing law clause.
General provisions
Precedence. In the event of any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA shall take precedence. For all other matters, the Terms of Service shall govern. Where a Controller has entered into a separate written agreement with RealTime.Photos that expressly supersedes these Terms of Service, that agreement also takes precedence over this DPA to the extent it expressly addresses any matter covered herein — including the limitation of liability applicable to claims arising under this DPA.
Term. This DPA remains in force for the duration of the Terms of Service and terminates automatically when the Terms of Service terminate or expire, subject to the Survival clause below.
Survival. The obligations under sections (b) Confidentiality, (c) Security, (f) Data breach notification, (g) Return and deletion, and (j) Records of processing survive termination of this DPA for as long as RealTime.Photos retains any personal data of the Controller, or for any longer period required by applicable law.
Limitation of liability. Each party's liability arising out of or related to this DPA is subject to the limitation of liability provisions set out in the Terms of Service. Nothing in this DPA is intended to expand either party's aggregate liability beyond the cap established in the Terms of Service.
Contact
For data protection enquiries, to exercise data subject rights, or to request a countersigned copy of this DPA, contact us at hello@realtime.photos with the subject line "DPA Request".